The Five-Hour Hack Window That Makes Every Business a Target

A newly disclosed software bug now takes hackers a weighted median of five hours to turn into a live, mass attack, according to new research from Patchstack, the Estonian threat-intelligence firm founded by Oliver Sild. The same research counted a record 11,334 new vulnerabilities across the WordPress ecosystem last year, a 42% jump in twelve months.

Sild built Patchstack to track that gap for a living. In a recent interview with The European Business Review, he described the underlying problem in blunt terms: building a website or an app has gotten radically easy, while the security knowledge needed to run one safely has not kept pace. The five-hour number is what happens when that gap goes unpriced long enough.

WordPress’s Worst Vulnerability Year Just Landed

Patchstack’s report, produced with malware intelligence firm Monarx, documents the worst year on record for the software running a huge share of the internet. WordPress now powers roughly 41.5% of all websites, according to the web technology survey firm W3Techs, making it the single largest software target pool on the open internet.

Patchstack logged a record 11,334 new vulnerabilities in 2025, up from 7,966 the year before. Highly exploitable vulnerabilities, the kind that let an attacker take over a site with little effort, rose 113% year over year. More high-severity bugs turned up in 2025 alone than in the previous two years combined.

Ninety-one percent of those vulnerabilities lived in plugins, the third-party add-ons that give WordPress sites their features. Just six showed up in WordPress core itself, and Patchstack rated all six low risk. The danger sits almost entirely in code bolted on afterward, not the platform’s foundation.

Metric 2025 Figure Why It Matters
New vulnerabilities disclosed 11,334 Up 42% from 7,966 in 2024
Highly exploitable vulnerabilities +113% year over year More high-severity bugs than the prior two years combined
Found in plugins vs. core 91% vs. six bugs Risk sits almost entirely in add-on code
Unpatched at public disclosure 46% Nearly half went live with no fix ready
Weighted median time to mass exploitation Five hours Measured across the most heavily targeted bugs

Nearly half of it arrived pre-broken. Forty-six percent of 2025’s vulnerabilities went public before the plugin maker had shipped a fix, meaning the flaw was live and known before any patch existed to close it.

How Fast Do Hackers Move After a Bug Goes Public?

Patchstack’s data puts the weighted median at five hours from disclosure to the first wave of mass exploitation. Among the most heavily targeted bugs, one in five saw attack traffic within six hours, 45% within a day, and 70% within a week, leaving almost no gap between a fix existing and an attacker using it.

That timeline breaks the old advice. Patching on a weekly or monthly cycle, long the standard recommendation for small teams, assumes defenders have days to react. Patchstack’s report puts it plainly: “Regular plugin updates are the second line of defence, but as attackers weaponize new vulnerabilities within mere hours, this is not a viable defence.”

The pattern is not unique to WordPress. Security researcher Jerry Gamblin’s annual review of the Common Vulnerabilities and Exposures (CVE) database counted 48,185 CVEs published in 2025, a new record, and found that WordPress security firms now out-publish tech giants like Microsoft and Google in raw vulnerability disclosures.

Estonia’s own cyber authority, the RIA (the country’s Information System Authority), logged a similar surge at home. It reported more than 48,000 vulnerabilities reported in 2025, up about 20% from 2024, and traced a breach at an Estonian library to unpatched email and content management software that had already reached the end of its supported life.

The Accessibility Bet That’s Coming Due

Sild traces the surge to something more basic than attacker skill. The tools for building on the web got easy long before the tools for securing it did. His own path into the field started in video games as a teenager, moderating servers where rivals would knock each other offline to steal players, before he studied computer networking and was later recruited into the Estonian Defence League’s cyber unit.

“Almost every company has a website today, regardless of whether they have dedicated technical staff,” Sild told The European Business Review. “That means they’re relying on technology they don’t fully understand, which often leads to security mistakes they don’t even realise they’re making.”

“Today, building a WordPress website or vibe-coding an application is accessible to almost anyone without a technical background,” he said. “What’s much harder is understanding that these systems require ongoing maintenance, updates, and security monitoring.”

  • Vibe coding – using an AI model to generate working code, often a plugin or a small app, without the person shipping it being able to fully audit what the model wrote. Patchstack’s 2026 report names it as a fast-growing source of unreviewed vulnerabilities.

The report backs him up directly. Patchstack’s findings single out vibe-coded plugins as their own risk category, noting that when the person shipping the code cannot review it for security flaws, vulnerabilities go live silently and stay that way until something breaks.

Hosting Providers Are Catching One Attack in Four

The safety net most site owners assume exists is thinner than advertised. Patchstack’s own penetration tests against popular hosting providers found their defenses stopped just 26% of vulnerability exploit attempts overall, and only 12% of attacks aimed specifically at WordPress.

Hosting companies including GoDaddy, Hostinger, DigitalOcean and Cloudways lean on Patchstack’s own technology to close part of that gap, deploying plugin-level protection automatically the moment a threat is confirmed. That 26% figure is not a rounding error. It is the reason regulators are now stepping into a space they used to leave alone.

Small Businesses Are Now the Most Common Targets

Everybody is a target.

Oliver Sild, founder and CEO of Patchstack, told The European Business Review that in response to the argument he hears most often from smaller companies.

“The most common argument I hear is, ‘We’re just a small company,’ or, ‘We don’t hold anything valuable,’” he said. Most attacks, he added, are carried out by automated bots that do not choose their targets. Simply gaining access to a site is already valuable, since attackers can repurpose the resources a business is already paying for. Any data they find after that is, in his words, “simply a bonus.”

  • Hosting and compute resources – the server capacity and bandwidth a business already pays for, repurposed to run the attacker’s own traffic.
  • A launchpad for further attacks – a foothold used to reach other targets down the line.
  • Whatever data happens to be there – customer records or credentials, described by Sild as a bonus rather than the goal.

Independent research backs the pattern. Verizon’s 2026 Data Breach Investigations Report found that 43% of all cyberattacks target small businesses, and that exploited vulnerabilities became the top initial access vector for breaches for the first time in 19 years, accounting for 31% of incidents. Yet research from StrongDM found that 59% of small-business owners with no security measures in place still believe they are too small to be worth attacking.

Closing that gap has less to do with budget than habits: basic inventory and access control, the kind laid out in a small business data privacy playbook built for exactly this kind of exposure.

The Shadow Inventory No One’s Watching

Visibility, not budget, is what Sild calls the biggest blind spot. “Many organisations don’t actually know what their websites and applications are made of, especially now that AI can generate large parts of them automatically,” he said.

“Employees increasingly build internal dashboards, automations, and AI-powered tools that connect directly to company data,” Sild said. “These projects often exist outside the visibility of IT teams.” The company doesn’t know they exist, and the employee usually lacks the security expertise to recognize where they’re vulnerable.

  • 45% of employees are now regular AI users on corporate devices, and shadow AI detections rose fourfold in a year, per Verizon’s 2026 Data Breach Investigations Report.
  • 64% of employees admit to using unauthorized AI tools for work, according to WatchGuard’s 2026 Cybersecurity Hygiene Report.
  • 67% of employees use AI tools at work, but only 18% of organizations have a formal AI security policy, per Salesforce’s 2026 Workforce AI Survey.
  • Organizations where AI significantly expanded the number of identities touching company data reported a 43% breach rate where AI expanded access, compared with 11% elsewhere.

The risk runs in both directions. The same tools employees adopt without approval are being used, in more extreme form, to run attacks with minimal human steering at all. Financial regulators were already paying attention before that became obvious. Canada’s early warning to banks about Anthropic’s Mythos landed months before this wider wave of scrutiny caught up.

Regulators Move to Close the Patching Gap

Brussels is trying to force the timeline forward. The EU’s Cyber Resilience Act (CRA) will require every commercial WordPress plugin to run a formal Vulnerability Disclosure Program, a structured channel for researchers to report flaws to developers before criminals find them first.

Sild’s own prescription is less about regulation and more about speed. “The window to respond keeps shrinking,” he said, “so organisations need to detect and fix issues much faster than they used to.”

Frequently Asked Questions

Are premium WordPress plugins safer than free ones?

Not necessarily, and Patchstack’s 2026 report flags the opposite risk. Premium plugins generally get less independent security review than free ones because outside researchers rarely have access to their source code, so vulnerabilities can sit undiscovered for longer. Price is not a reliable signal of security in the WordPress ecosystem.

What is a Vulnerability Disclosure Program, and why is the EU making it mandatory?

A Vulnerability Disclosure Program, or VDP, is a formal channel that lets outside researchers report security flaws to a software maker before going public with them. The EU’s Cyber Resilience Act will require one for every commercial WordPress plugin, part of a broader push to close disclosure gaps across the ecosystem.

How can a small business tell if its website has already been compromised?

Warning signs include unexpected spikes in hosting or bandwidth usage, unfamiliar admin accounts, site traffic silently redirected elsewhere, and hosting providers flagging unusual outbound activity. Sild’s own point is that attackers often just want to borrow paid-for server resources, so a compromise can run quietly for months without any data ever going missing.

How much does a data breach actually cost a small business?

IBM’s data breach research puts the average cost for a business with fewer than 500 employees at $3.31 million once investigation, downtime, notification and recovery are counted. That figure sits well above what most small businesses budget for security in a given year.

Does cyber insurance cover damage from automated bot attacks?

It can, but adoption is thin. Only about 17% of small businesses in the United States carry cyber insurance, compared with 62% in the United Kingdom, according to industry survey data. Insurers generally assess the outcome of an incident rather than how deliberate the attacker was, so automated exploits are typically covered the same as targeted ones.

Leave a Reply

Your email address will not be published. Required fields are marked *